Is CA Spectrum affected by Struts 2 Vulnerability CVE-2017-5638?
Release: SDBSFO99000-10.2-Spectrum-Device Based Suite-Server FOC
CA Spectrum 10.2.1 and above comes with Strust 2.3.32 which is not vulnerable to this CVE.
However, previous versions are vulnerable.
There is no workaround for the release of Struts that CA ships with versions prior to 10.2.1.
CA highly suggests customers upgrade to 10.2.1 or above to obtain the fix for this vulnerability.
It has been classified as a high threat / Critical.
Please see CVE details on Apache's documentation:
And NVD Details:
CAPM and CAPC are also not affected by this vulnerability: